[ Applies to ] StorageGuard / CTERA / Cloud Storage & STaaS
This article lists the recommended baseline checks for CTERA. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
CTERA is an enterprise edge-to-cloud file services platform. The CTERA Portal provides centralized management for physical and virtual Edge Filers, delivering a global file system across branch offices, remote users and cloud storage.
Why hardening CTERA matters
CTERA deployments manage sensitive data spread across many edge locations. End-to-end encryption, role-based access, tenant isolation and centralized auditing are essential, because weak controls at the edge can expose data or increase the risk of loss and compliance violations.
Recommended baseline checks
The baseline below contains 73 checks, listed alphabetically.
| ID | Configuration check | Component |
|---|---|---|
| SG-C0196T259V01 | Access control list status | CTERA Portal |
| SG-C0214T259V02 | Admin authority level - Read-only settings | CTERA Portal |
| SG-C0214T259V01 | Admin authority level - Super-user grant | CTERA Portal |
| SG-C0940T259V01 | Alert minimum severity threshold | CTERA Portal |
| SG-F1010T259V01 | Alert required origin types | CTERA Portal |
| SG-F8537T259V01 | Alert required topics | CTERA Portal |
| SG-F5114T259V02 | Antivirus exclusions - Limited scope | CTERA Portal |
| SG-F5114T259V01 | Antivirus exclusions - Required | CTERA Portal |
| SG-C0451T259V01 | Antivirus scan status | CTERA Portal |
| SG-C0163T259V01 | Approved AD domain | CTERA Portal |
| SG-C0941T259V01 | Approved device types | CTERA Portal |
| SG-C0933T259V01 | Approved directory service type | CTERA Portal |
| SG-F8098T259V01 | Approved SAML IdP configuration | CTERA Portal |
| SG-C0919T259V01 | Auto delete zero quota files | CTERA Portal |
| SG-C0911T259V01 | Automatic software updates enabled | Edge Filer |
| SG-C0930T259V01 | Backup deduplication level | CTERA Portal |
| SG-C0932T259V01 | Backup delay interval threshold | CTERA Portal |
| SG-F8878T259V01 | Backup extended attributes | CTERA Portal |
| SG-F7538T259V01 | Backup policy coverage | CTERA Portal |
| SG-F8732T259V01 | Backup success | CTERA Portal |
| SG-F6209T259V01 | Central authentication | CTERA Portal |
| SG-C0536T259V01 | Client backup status | Managed devices |
| SG-F7908T259V01 | Client IP access control list | CTERA Portal |
| SG-C0923T259V01 | Cloud Drive Logging | CTERA Portal |
| SG-C0922T259V01 | Cloud Pro Directory status | CTERA Portal |
| SG-C0065T259V01 | Data at-rest encryption | CTERA Portal |
| SG-F9002T259V01 | Device time zone | Edge Filer |
| SG-C0912T259V01 | Edge filer admin remote access | Edge Filer |
| SG-C0926T259V01 | Email confirmation for new accounts | CTERA Portal |
| SG-C0571T259V01 | Encryption password - backup protection | CTERA Portal |
| SG-C0600T259V01 | End of support | CTERA Portal |
| SG-C0600T260V01 | End of support | Edge Filer |
| SG-C0600T259V02 | Future end of support | CTERA Portal |
| SG-C0600T260V02 | Future end of support | Edge Filer |
| SG-C0068T259V01 | Hardware-based encryption status | Edge Filer |
| SG-C0381T259V01 | HTTP service status | CTERA Portal |
| SG-C0381T259V02 | HTTP service status - Portal HTTPS | CTERA Portal |
| SG-F9461T259V01 | Inactive user accounts | CTERA Portal |
| SG-C0927T259V01 | Invitation authentication required | CTERA Portal |
| SG-F6601T259V01 | Invitation protection level | CTERA Portal |
| SG-C0038T259V01 | Kerberos status | CTERA Portal |
| SG-C0120T259V01 | LDAP incorrect role mapping | CTERA Portal |
| SG-C0394T259V01 | Mail (SMTP) settings | CTERA Portal |
| SG-C0239T259V01 | Multi-factor authentication | CTERA Portal |
| SG-F8284T259V01 | Non-default Edge Filer admin username | Edge Filer |
| SG-C0231T259V01 | Non-default local users | CTERA Portal |
| SG-C0921T259V01 | Office Online access status | CTERA Portal |
| SG-F6423T259V01 | Password policy - Complexity | CTERA Portal |
| SG-F6798T259V01 | Password policy - History | CTERA Portal |
| SG-F7060T259V01 | Password policy - Maximum age | CTERA Portal |
| SG-F7154T259V01 | Password policy - Minimum age | CTERA Portal |
| SG-C0929T259V01 | Projects folders disabled | CTERA Portal |
| SG-C0931T259V01 | Remote access redirect policy | CTERA Portal |
| SG-C0537T259V01 | Required firmware version | Edge Filer |
| SG-F1257T259V01 | Required notifications | CTERA Portal |
| SG-F3796T259V01 | Required Portal version | CTERA Portal |
| SG-C0505T259V01 | Retention policy | CTERA Portal |
| SG-C0505T259V02 | Retention policy - Deleted files | CTERA Portal |
| SG-C0935T259V01 | SAML sign-in URL uses HTTPS | CTERA Portal |
| SG-C0943T259V01 | Secure HTTP for Portal GUI URLs | CTERA Portal |
| SG-F3354T259V01 | Secure remote access URL | Edge Filer |
| SG-C0404T259V01 | Security email notification | CTERA Portal |
| SG-C0924T259V01 | Self registration status | CTERA Portal |
| SG-C0928T259V01 | Sharing personal folders disabled | CTERA Portal |
| SG-C0920T259V01 | Simplified connect mode | CTERA Portal |
| SG-C0442T259V01 | Single Sign-On (SSO) status | CTERA Portal |
| SG-C0557T259V01 | SMB hide snapshots | CTERA Portal |
| SG-C0116T259V01 | Unapproved admin users | CTERA Portal |
| SG-C0116T259V02 | Unapproved admin users - AD-sourced admins | CTERA Portal |
| SG-C0213T259V01 | Use of secure LDAP | CTERA Portal |
| SG-C0934T259V01 | Voucher required when voucher support enabled | CTERA Portal |
| SG-F9330T259V01 | Watermark enabled | CTERA Portal |
| SG-F8544T259V01 | WebDAV hide previous versions | CTERA Portal |
Related components
A complete baseline also covers the components that manage, connect to or protect CTERA. Review the configuration of:
- CTERA Portal
- CTERA Edge Filers
- CTERA Drive clients
- Back-end object storage
- Active Directory, LDAP and SAML identity providers
- SMTP mail relay used for Portal notifications
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.